[TLS] Re: PSK identifier (and binder) lengths in the TLS 1.3 outer ECH?

Viktor Dukhovni <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <[email protected]>
On Fri, Aug 14, 2026 at 08:40:49AM -0400, David Benjamin wrote:

> > When there's a broader movement to drop the F5 workaround padding,
> > I'd love to drop that as well.
> 
> Oh, that's a good reminder. I had meant to go remove it. Now that
> ClientHellos have ML-KEM key shares, this is moot because they're never in
> the problem range anymore. :-)
> 
> I would hope, by now, all the F5s have been updated, but the failure
> condition was a timeout, which made measurements difficult. But happily now
> it doesn't matter. The bookkeeping is indeed a pain.

That's perhaps easier for Chromium if the MLKEM keyshare prediction is
unconditional.  In OpenSSL the configuration file and/or application
esttings can tweak keyshare prediction to give a CH size in the F5
danger-zone, and I don't know whether there's any reason to still care.

Are there still somewhere out of view users lovingly maintaining and
getting useful service from unpatched F5's dating back to ~2014?

-- 
    Viktor.  🇺🇦 Слава Україні!

_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.